Self-Service Identity
Identity solution
Let users complete identity tasks safely without waiting for the helpdesk—while keeping verification, account actions, and notifications under NIM control.
At a glance
NIM self-service supports verified password reset and onboarding workflows without sending users their credentials. Password reset verifies the person before allowing a reset; onboarding verifies the owner of a prepared account, lets them choose a first password, and activates access.
Before publishing: provide secure HTTPS access, current contact data for verification, and working email or SMS delivery. Test the complete end-user journey with a safe record before making either workflow available to users.
Choose the experience
Reset a forgotten password
Verify identity with a one-time passcode, then allow the user to reset their own password.
Build password reset →Onboard a new user
Verify a prepared account owner, set a first password, and activate access without sending credentials.
Build onboarding →Both experiences need secure HTTPS access, reliable contact data, and configured notification delivery. Use email settings and, where required, SMS settings before testing with users.
Choose the right self-service pattern
| User need | Recommended NIM experience | Required control |
|---|---|---|
| A user has forgotten a password | Self-service password reset | Verify the person before the reset, then enforce the target password policy. |
| A new user needs to activate a prepared account | Onboarding | Verify the prepared account owner, let the user choose the first password, and activate access without disclosing credentials. |
| An approved user must request or perform another defined identity task | NIM App | Grant access only to the approved users or groups and configure only the actions the form requires. |
Use a user-facing workflow when a person must provide information, prove control of a contact method, make a choice, or receive a controlled exception. Use a scheduled mapping, role, or job when trusted source data already determines the change and no user interaction is required.
Test before publishing
- Confirm the published URL is available through HTTPS and that the intended users can reach it.
- Verify the email or SMS delivery path with a safe test contact method.
- Run the complete journey with a safe record, including verification, form input, target-system action, and resulting notification.
- Confirm the target account, password, or access state has the intended result.
- Check that an unauthorized or unrelated user cannot access the experience or complete the action.
If a self-service action does not produce the expected target change, review its configured action and then use Troubleshoot NIM provisioning failures to check the related filter, mapping, connector access, and job result.